Live data from Hacker News

Show HN: OpenSign – Open source alternative to DocuSign

github.com

81–90 of 164 posts

Re: Show HN: OpenSign – Open source alternative to DocuSign

#81

Earlier quoted context omitted.

Yes, making a mill for supposedly trusted third parties, over having an actual trusted third party, is a more open way. Edit: I suppose in all except the free self hosted one, OpenSign would be the trusted third party, which I guess is more plausible. Unless the paid customers are given something close to root to administrate them. Still, a trusted third party is generally based on recognition. Even if I really disli…

Great insights. The hosted version functions in a more or less same way as DocuSign with an added advantage of knowing what the code is doing under the hood. We dont intend to provide root/admin privileges as its going to be a multi-tenant system at the end of the day.

Ah, I see. A multi-tenant system makes sense, I was thinking it might be closer to managed hosting. With managed often people have root or close to it. Just make sure people understand that it’s a multi-tenant system where the customers don’t have access to do anything which would make it less secure, unless they’re using the self-hosted version. And when you grow, maybe there will be an enterprise self-hosted and/or managed hosting version where the customer needs to be trusted to provide security. That would be appropriate with some potential customers.

So that leaves the challenge of becoming a well known trusted third party, which is a challenge but doable.

Re: Show HN: OpenSign – Open source alternative to DocuSign

#82

Earlier quoted context omitted.

Yeah, and a while ago there seemed to be people who didn't think it was F/OSS, and wanted to avoid it because it might reduce the likelihood of someone contributing. One thing I do think that people misunderstand is that a company can absolutely take your project and run it as a service -- they just have to contribute code back if/when they modify it. The real canary is requiring signed CLAs.

True. Someone here in another comment has already pointed out that this project's CLA demands that all submissions have to be under the MIT license! This seems shady and can be perceived as an attempt to "steal" code in the future (MIT licensed code can be incorporated into xGPL license code, but it doesn't prevent the original license holder of the xGPL product to close source the product in the future. If the contr…

I don't see that they have a CLA -- I can only find their note about the license contributors must take[0].

I guess that's one way around the CLA -- they don't need one if they force all contributions to be MIT in a file most people wouldn't read.

In the end people the actual likelihood of someone making a credible legal threat is low so it all seems somewhat spurious but great way to go around the overt beacon that requiring CLA signing is.

[0]: https://github.com/OpenSignLabs/OpenSign/blob/bb846442ecbaa3...

Re: Show HN: OpenSign – Open source alternative to DocuSign

#83

Earlier quoted context omitted.

The self hosted version will always be free :)

Your CONTRIBUTING.md file says "By contributing, you agree that your contributions will be licensed under its MIT License." Since OpenSign is AGPLv3, why don't you allow contributions under the same license, if the self hosted version will always be free? I'm worried that the purpose of that might be to let you make it proprietary later.

AGPL for thee but not for me, for I require MIT.

To be fair, this is an entirely reasonable way to do business, but it's also a bit funny.

Re: Show HN: OpenSign – Open source alternative to DocuSign

#84

Earlier quoted context omitted.

Our understanding is that DocuSign does not have any legal authority, they prove the chain of custody/modifications using digital traces which our solution can also do, arguably in a more open way.

One think that I think they provide (as opposed to the self hosted version) is just the fact of being a relatively neutral third party. If there’s a dispute over the veracity of a signature, it’s probably helpful to have a third party say “according to our server logs and software stack, this was signed by johndoe@example.com at 12:41pm on August 3rd, from the IP address XX.XXX.XXX.XX, and they authenticated with the…

Late to the party here, but I deal in this space all day. You are 100% correct.

Disputes over eSignatures come up allllll the time. And if you mention that it was "DocuSigned"... although you have done nothing aside from name-dropping... it will essentially end the dispute. Not saying that it should. Just saying that it does.

Re: Show HN: OpenSign – Open source alternative to DocuSign

#85
post #2

My understanding (possibly incorrect) is that competing with DocuSign is hard because of the need to follow obscure state and National laws (many of which are defined by case law rather than published law) in order for the signatures to be legally binding. Is that the case? And if so, is there evidence OpenSign has done this kind of SME research to make sure the electronic signatures are legally binding, or is this m…

Your overall understanding is correct. People pay DocuSign to "think" of everything for them (which is not at all bad, it just comes at a cost). Depending on the space, you have to deal with crazy laws that no one in their right mind would know about (nor think to even consider).

Essentially, "no one ever got fired for signing with DocuSign" (play on IBM).

I'm late to the party here, but if the authors want real world examples, please reach out.

Re: Show HN: OpenSign – Open source alternative to DocuSign

#86
post #2

My understanding (possibly incorrect) is that competing with DocuSign is hard because of the need to follow obscure state and National laws (many of which are defined by case law rather than published law) in order for the signatures to be legally binding. Is that the case? And if so, is there evidence OpenSign has done this kind of SME research to make sure the electronic signatures are legally binding, or is this m…

Lawyer here. Not legal advice. Really not that much by way of law to consider. If everyone agrees that an E-signature is good, then, generally speaking, an e-signature is good. I’d suggest it’s more on the people actually drafting the documents being signed than the software layer facilitating.

Re: Show HN: OpenSign – Open source alternative to DocuSign

#87

Earlier quoted context omitted.

True. Someone here in another comment has already pointed out that this project's CLA demands that all submissions have to be under the MIT license! This seems shady and can be perceived as an attempt to "steal" code in the future (MIT licensed code can be incorporated into xGPL license code, but it doesn't prevent the original license holder of the xGPL product to close source the product in the future. If the contr…

I don't see that they have a CLA -- I can only find their note about the license contributors must take[0]. I guess that's one way around the CLA -- they don't need one if they force all contributions to be MIT in a file most people wouldn't read. In the end people the actual likelihood of someone making a credible legal threat is low so it all seems somewhat spurious but great way to go around the overt beacon that…

For a project that deals with signatures it should be pretty obvious that this does not quite work in a legally sound way. At least in the PR they will need some prove that I acknowledge to have read this Contributing.md. They is a reason why people go through the hassle of CLA signing flows. Wonder why they do not dog food their own system.

Re: Show HN: OpenSign – Open source alternative to DocuSign

#88
post #2

My understanding (possibly incorrect) is that competing with DocuSign is hard because of the need to follow obscure state and National laws (many of which are defined by case law rather than published law) in order for the signatures to be legally binding. Is that the case? And if so, is there evidence OpenSign has done this kind of SME research to make sure the electronic signatures are legally binding, or is this m…

Wouldn’t it be amazing, since e signatures have been around for ages, that governments just published the requirements for legally binding digital signatures rather than ask each maker to go talk to them and get some obscure license or blessing?

In the EU this is actually the case since 2016. There's this regulation called eIDAS (electronic IDentification, Authentication and trust Services).

Article 26 (linked below) describes the requirements for an electronic signature to be legally binding.

https://www.eid.as/#article26 https://en.m.wikipedia.org/wiki/EIDAS

Re: Show HN: OpenSign – Open source alternative to DocuSign

#90

How does something like this avoid IP theft/infringement cases? By all accounts it’s functionally the same thing as DocuSign? I ask because I am genuinely curious and hoping to learn a bit about IP law.

What kind of issue do you have in mind? By all accounts, the functionality or OpenOffice, LibreOffice, and Google’s suite are the same as Microsoft Office. There’s no theft unless they _actually stole intellectual property_
Post reply on HN